- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Vulnerability in sendmail(1M) Versions Prior t...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-28-2006 02:27 AM
03-28-2006 02:27 AM
# what /usr/sbin/sendmail
/usr/sbin/sendmail:
Copyright (c) 1998 HEWLETT PACKARD COMPANY and its licensors,
including Sendmail, Inc., and the Regents of the
University of California. All rights reserved.
version.c 8.9.3.1 (Berkeley) 10/10/2003 (PHNE_29774)
Check these site for security vulnerability.
US-CERT Technical Cyber Security Alert TA06-081A:
http://www.us-cert.gov/cas/techalerts/TA06-081A.html
Sendmail MTA Security Vulnerability:
http://www.sendmail.com/company/advisory/
See also http://www.frsirt.com/english/advisories/2006/1049
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-28-2006 02:44 AM
03-28-2006 02:44 AM
Re: Vulnerability in sendmail(1M) Versions Prior to 8.13.6 ??
The vulnerability is in ALL sendmail versions before 8.13.3
HP may decide to release a patch versus a whole new sendmail, as may other vendors.
To deal with the vulnerability you must either upgrade sendmail or install a certified patch set.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-28-2006 02:46 AM
03-28-2006 02:46 AM
Re: Vulnerability in sendmail(1M) Versions Prior to 8.13.6 ??
Yes, This Vulnerability exists on all versions of Sendmail prior to 8.13.3. You can download the latest source from http://www.sendmail.org/8.13.6.html and install yourself.
-Arun
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-28-2006 02:47 AM
03-28-2006 02:47 AM
Re: Vulnerability in sendmail(1M) Versions Prior to 8.13.6 ??
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-28-2006 02:49 AM
03-28-2006 02:49 AM
Re: Vulnerability in sendmail(1M) Versions Prior to 8.13.6 ??
You can go to this website and get a utility to run on your HP-UX box which will tell you all of the current security patches you need to install:
http://docs.hp.com/en/B2355-90950/ch08s19.html?jumpid=reg_R1002_USEN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-28-2006 02:49 AM
03-28-2006 02:49 AM
Re: Vulnerability in sendmail(1M) Versions Prior to 8.13.6 ??
The command should already be on your system.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-28-2006 02:51 AM
03-28-2006 02:51 AM
Solutionhttp://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=SMAIL813
This one is probably NOT vulnerable according to my reading of the docs.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-28-2006 03:08 AM
03-28-2006 03:08 AM
Re: Vulnerability in sendmail(1M) Versions Prior to 8.13.6 ??
Does this mean HP (unlike Sun) does not have a patch to address this particular vulnerability issue ?
Kent,
does this new version of patch fix this particular problem ? At this porint, I don't want install all security patches but just this problem.
SEP,i am gathering that since we don;t have a patch we may have to upgrade sendmail by swremove old sendmail and
swintall new one.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-28-2006 08:06 AM
03-28-2006 08:06 AM
Re: Vulnerability in sendmail(1M) Versions Prior to 8.13.6 ??
Thanks toall